The purpose of this policy is to provide guidance and support for information security management in accordance with the requirements of medical activity and applicable regulations.
This policy contains a description of key elements, both human and organizational, technological and documentary, that ASCIRES Grupo Biomédico (hereinafter ASCIRES) applies to protect information, and especially personal data, preventing security incidents that endanger them.
At all levels of ASCIRES, the real and effective application of the prevention and control measures provided for in this policy will be ensured, so that this management system achieves the elimination or reduction of behaviors that may endanger the security of information assets and personal data processed by ASCIRES.
This policy will be adapted to the technological and legislative changes that occur. in the future.
ASCIRES' fundamental objective is to provide patients with precision diagnostic services, radiotherapy treatments, nuclear medicine, as well as specialized and personalized care in medical consultations with outpatient surgery.
The vocation for the patient, the passion for technological innovation and the humanization of treatment are the hallmarks shared by ASCIRES. Due to its technology and the number of patients treated annually, ASCIRES is the pioneering biomedical group in Spain in Diagnostic Imaging and Nuclear Medicine, as well as a benchmark in Radiotherapy Oncology.
ASCIRES, within its scope of action, provides services related to activity within the healthcare sector.
This means that its main assets are intangible in nature and are mainly made up of confidential information, such as patient medical information or information related to scientific research, personal data, intellectual property, industrial property, among others.
The intangible nature of this type of assets makes them very vulnerable to internal and external threats such as unauthorized access, unauthorized copying, disclosure, transfer to third parties, unauthorized use, unauthorized exploitation and even destruction.
The protection of information assets requires a series of legal, technical and organizational measures that are summarized in this policy and detailed in the rules and procedures of ASCIRES.
This policy applies to the following areas of ASCIRES:
Based on the above, and taking into account the requirements applicable to ASCIRES in terms of security, the following formal scope is established, which defines the areas that must comply with the specifications of the National Security Scheme:
“The information systems that support the radiodiagnostic and nuclear medicine services that support healthcare and non-healthcare processes and activities in accordance with the current categorization document.”
National and European:
Guides and standards:
Registry of applicable Guides: “Control Guides Applicable”.
Ascires Protection Policy.
The objective of information security is to guarantee the quality of the information and the continued provision of services, acting preventively, monitoring daily activity and reacting diligently to incidents.
The systems managed by ASCIRES must be managed diligently, taking appropriate measures to protect them against accidental or deliberate damage that may affect the availability, integrity or confidentiality of the information processed or the services provided.
To defend against these threats, a strategy is required that adapts to changes in the conditions of the ASCIRES environment and thus guarantee the continued provision of services. services.
Certain areas that make up ASCIRES must apply the minimum security measures required by the National Security Scheme, since they provide services to the Public Administration, as well as continuously monitor the levels of service provision, follow and analyze reported vulnerabilities, and prepare an effective response to incidents to ensure the continuity of the services provided.
The different departments must ensure that security in information systems is an integral part of each stage of the system's life cycle, from its conception to its withdrawal from service, including development or acquisition decisions and exploitation activities.
The departments must be prepared to prevent, detect, react to and recover from security incidents, in accordance with Article 8 of the ENS.
The objectives of ASCIRES in terms of information security are aligned with those of medical activity, giving priority to compliance with the legal obligations that are applicable to the activity carried out.
Compliance with the General Data Protection Regulation of the European Union and the regulations regarding the protection of personal data in force in the countries in which ASCIRES operates is considered a priority objective of information security.
At all levels of ASCIRES there will be a commitment to comply with the objectives set in terms of information security and to apply the established controls.
The ASCIRES security strategy will comply with the principles of confidentiality, integrity, availability, authenticity and traceability of information.
The principle of confidentiality guarantees that information is only accessible to users authorized to access it and that it cannot be disclosed to third parties without the corresponding authorization.
The principle of integrity guarantees that data will be kept free from unauthorized modifications and that existing information has not been altered by unauthorized persons or processes.
The principle of availability guarantees that information will be accessible and usable on a constant basis, ensuring the continuity of processes and medical activity. This principle is linked to the principle of resilience, which consists of ensuring the ability of systems and information to recover after an incident that prevents temporary access to them.
The principle of authenticity guarantees that the origin and identities associated with the information are really those that appear in its attributes. This principle is linked to the principle of non-repudiation, which consists of ensuring that a user cannot deny the authorship of an act in the system or the link to a piece of data or set of data.
The principle of traceability guarantees the possibility of determining at any time the identity of the people who access the information and the activity they carry out in relation to it, as well as the different states and routes that the information has followed.
A principle of proportionality will be applied between the controls to be applied and the severity of the risk to be prevented, detected or mitigated.
In new services and developments, the principle of security by design and by default will be applied.
All roles and responsibilities will be differentiated and assigned individually in the job description. In addition to this individualized assignment, all persons belonging to ASCIRES, regardless of the level, will be obliged to comply with the rules, procedures and controls established in terms of information security.
The highest authority for control in terms of information security will correspond to the administrative body, which will be supported by the Data Protection and Information Security Committee, which includes the Chief Information Security Officer (CISO), who will be responsible for ensuring compliance with this policy and reporting any relevant issue to the Committee.
ASCIRES may develop rules and procedures that develop, specify and detail the control measures indicated in this policy.
When managing In terms of information security, ASCIRES has taken international standards such as ISO 27001 as a reference; however, considering that ASCIRES also provides specific services to the Public Administration, the provisions of the National Security Scheme are also applied.
In accordance with article 12.1 of Royal Decree 311/2022, of May 3, which regulates the National Security Scheme, clear persons responsible for ensuring compliance with the Security Policy must be identified and must be known by all members of ASCIRES.
ASCIRES will adopt the necessary measures so that staff are comprehensible about the security regulations that affect the development of their functions, as well as the consequences that could be incurred in the event of non-compliance.
* The following roles are established in ASCIRES related to Information Security:
|
ROLES |
FUNCTIONS |
|
Service Manager |
Determine the security requirements of the services provided, for which purpose the impact of an incident affecting the security of the services with harm to availability, authenticity, integrity, confidentiality or traceability will be assessed. |
|
Information Manager |
Determine the security requirements of the information processed, for which he/she will assess the impact that an incident affecting the security of the information with damage to the availability, authenticity, integrity, confidentiality or traceability would have. |
|
Security Manager |
He/she will determine the decisions to satisfy the security requirements of the information and the services, supervising the implementation of the necessary measures and reporting on these issues. |
|
System Manager |
He/she will be responsible for developing the specific way of implementing security in the system and for supervising its daily operation, being able to delegate to administrators or operators under his/her control. responsibility |
|
Security Administrator |
He is in charge of the technical security tasks, who executes them. |
The Service Manager has the following associated functions:
Establishes the security requirements of the services. Within the framework of the ENS, it is equivalent to the power to determine the security levels of the Service.
The person responsible for the Information System has the following associated functions:
He has the ultimate responsibility for the use made of certain information and,
therefore, for its protection.
The Information Security Manager has the following associated functions:
|
ROLES |
DESIGNATION |
|
Service Manager |
The functions of the ASCIRES Service Manager will be assumed by the Director of Operations |
|
Information Manager |
The functions of the ASCIRES Information Manager will be assumed by the Director of Operations Director of Operations |
|
Security Officer |
The functions of the ASCIRES Information Security Officer will be assumed by the Chief Information Security Officer (CISO) |
|
System Manager |
The functions of the System Manager at ASCIRES will be assumed by the IT Infrastructure Systems Manager. |
|
Administrator of the Security |
The functions of the Security Administrator at ASCIRES will be assumed by the IT Infrastructure Systems Manager. |
This is the body that coordinates Information Security at an internal level at ASCIRES.
It will be made up of the Service Manager, the Security Manager, the Information Manager and the System Manager.
Likewise, the DPO and the Legal Department Director will be integrated into the Data Protection and Information Security Committee, whose functions are detailed in the Data Protection Policy.
The Data Protection and Information Security Committee will have the following functions:
The Security Officer will assume the functions of the secretariat of the Data Protection and Information Security Committee, which will be those detailed below:
The Information Security Officer will transfer to the ASCIRES Data Protection and Information Security Committee those aspects that have been discussed with the Security Officer when they must be managed jointly with the City Council.
The hierarchy of roles is described as follows:
The Information Security Officer reports to the Management of the organization, as agreed in the Data Protection and Information Security Committee.
The vote or decision of the Information Security Officer will prevail in the event of a tie in the decisions taken by the other members of the Data Protection and Information Security Committee. Information.

All systems subject to this Policy must perform a risk analysis, assessing the threats and risks to which they are exposed.
ASCIRES periodically and continuously performs a risk analysis of the threats that affect information security.
The risk analysis is performed through an inherent risk map, in which the gross risks existing before the application of prevention, detection and mitigation controls are assessed, and through a residual risk map, in which the net risks existing after the application of controls are assessed.
The risk analysis will be the basis for determining the security measures that must be adopted in addition to the minimums established by the National Security Scheme, as provided for in Article 7 9.2 RISK ASSESSMENT CRITERIA
In order to harmonize risk analyses, the Data Protection and Information Security Committee will establish a reference assessment for the different types of information handled and the different services provided.
The detailed risk assessment criteria will be specified in the risk assessment methodology that ASCIRES will develop, based on recognized standards and good practices.
At least, all risks that may seriously impede the provision of services or the fulfillment of ASCIRES' mission must be addressed.
Special priority will be given to risks that imply a cessation of the provision of services to citizens.
At all levels of ASCIRES, there will be an obligation to immediately communicate the information security risks that are being handled. identify.
These risks will be communicated through the channels that ASCIRES has enabled to communicate any type of threat to people, assets or regulatory compliance.
Risk analysis and its treatment must be a regularly repeated activity, as established in Article 10 of the ENS. This analysis will be repeated:
ASCIRES processes personal data. The Register of Processing Activities, which will only be accessible to authorized persons, includes the affected processing and the corresponding controllers.
All ASCIRES information systems will comply with the security required by the regulations on personal data protection in accordance with the risk analysis carried out for the nature and purpose of the personal data collected in the Register of Processing Activities of the organization.
The areas that make up ASCIRES must avoid, or at least prevent as far as possible, that the information or services are harmed by security incidents.
To do this, the areas that make up ASCIRES must implement the minimum security measures determined by the ENS, as well as any additional control identified through a threat and risk assessment.
These controls, and the security roles and responsibilities of all personnel, should be clearly defined and documented.
To ensure compliance with the policy, areas or departments should:
Since services can be rapidly degraded by incidents, ranging from a decrease to a cessation of the level of provision, services should continuously monitor the operation to detect anomalies in the levels of service provision and act accordingly.
Training may be based on face-to-face sessions or e-Learning courses. This training may be based on any type of communication and training material and instruments that allow awareness of criminal risks at all levels of ASCIRES.
ASCIRES will perform the following functions in terms of training and awareness:
Compliance with this Security Policy is mandatory for all internal or external personnel involved in ASCIRES processes, with the consequences of non-compliance with the Security Policy being those established in the regulations in force in each country. moment.
When services are provided or information is managed for other organizations, they will be made aware of this Information Security Policy, which is published on the ASCIRES website and headquarters. Channels will be established for reporting and coordination of the respective Security Committees and procedures will be established for action to react to security incidents.
When third-party services are used or information is transferred to third parties, they will be made aware of this Security Policy and the Security Regulations that apply to said services or information. Said third party will be subject to the obligations established in said regulations, and may develop its own operating procedures to satisfy them.
Specific procedures for reporting and resolving incidents will be established.
When any aspect of the Policy cannot be satisfied by a third party as required in the previous paragraphs, a report will be required from the Security Manager specifying the risks incurred and how to deal with them. Approval of this report by those responsible for the information and services affected will be required before proceeding.
In addition to the legal requirements regarding security, ASCIRES is also obliged to comply with the specific security requirements demanded by its clients and suppliers in relation to the information they access by virtue of their contractual relationships with them.
ASCIRES will create and maintain an updated map of contractual obligations in which the obligations related to the security of the confidential information and personal data it accesses or processes will be identified and prioritised.
It will be ensured that third-party personnel are adequately aware of security, at least at the same level as that established in this Policy.
ASCIRES will periodically check that the contractual obligations assumed in terms of security are integrated into this security policy or into the rules and procedures that develop it. Otherwise, this integration will be carried out.
This document has been approved on 10/01/2023.
This Information Security Policy is effective from that date and until it is replaced by a new Policy.
It will be reviewed by the Security Officer at planned intervals, which may not exceed one year in duration, or whenever significant changes occur, in order to ensure that its suitability, adequacy and effectiveness are maintained.
Changes to the Information Security Policy must be approved by the corresponding competent higher body, in accordance with article 13 of the ENS.
Any changes to it must be disseminated to all parties affected.
Ascires grupo biomédico es consciente de la importancia de proteger su privacidad, por ello, ha dispuesto de la presente Política de Privacidad a los efectos de comunicarle de la manera más transparente posible cómo serán utilizados sus datos de carácter personal en el caso de que decida facilitárnoslos.
En adelante nos referiremos al conjunto de todas ellas como “Ascires”, son conscientes de la importancia de proteger su privacidad, por ello, ha dispuesto de la presente Política de Privacidad a los efectos de comunicarle de la manera más transparente posible cómo serán utilizados sus datos de carácter personal en el caso de que decida facilitárnoslos.
El tratamiento de sus datos de carácter personal por parte de ASCIRES se basará en los siguientes principios:
De forma adicional a la presente política, cada uno de los apartados y formularios dispuestos en la página web a través de los que se recogen datos de carácter personal cuenta con información específica acerca del tratamiento de los datos obtenidos a través de dicho canal.
La información que encontrará en cada formulario y que se complementará con la “Información Adicional” facilitada en la presente Política para cada formulario web, será la siguiente:
Finalidad/es
Se incluirá el propósito o propósitos que se persiguen con el tratamiento de sus datos de carácter personal.
Base jurídica del tratamiento
Cada formulario incluye la base jurídica que legitima del tratamiento de sus datos de carácter personal, tanto en aquellos casos en los que se trate de su consentimiento como cualquier otra base reconocida por la legislación vigente.
Destinatarios
Identidad o categorías de aquellos que puedan recibir la comunicación de sus datos de carácter personal.
Plazos de conservación de los datos o criterios para su determinación
Plazo o criterios para determinar el plazo durante el cual sus datos serán tratados para las finalidades comunicadas.
Existencia de decisiones automatizadas o elaboración de perfiles
Cabe la posibilidad de que utilicemos herramientas de segmentación con la finalidad de ofrecerle comunicaciones comerciales adaptadas a sus intereses. En el caso de que así sea, le ofreceremos información concreta al respecto en el formulario de la página web a través del cual facilite sus datos.
Forma de prestar el consentimiento
Tras su consentimiento para el tratamiento de sus datos, se le informará de la acción requerida para considerar que ha prestado dicho consentimiento.
Consecuencias de la no prestación del consentimiento
Cabe la posibilidad de que, si no nos presta su consentimiento, no podamos prestarle el servicio requerido.
Tratamientos en terceros países
En el caso de que sus datos vayan a ser tratados en países no pertenecientes a la Unión Europea, se le informará de la existencia o no de decisión de adecuación de la Comisión Europea y/o las garantías adoptadas para la protección de sus datos.
Ejercicio de sus derechos
Ver apartado 3.
Datos de contacto del Delegado de Protección de Dato o Data Protection Officer (DPO)
Ver apartado 4.
Información específica sobre el tratamiento de sus datos de carácter personal facilitados a través de cada apartado web.
Apartado “CONTACTO” https://www.ascires.com/hospital/contacto
Información adicional de protección de datos
Finalidad/es
La finalidad del tratamiento de los datos de carácter personal facilitados a través del presente formulario es la de resolver la consultar que nos plantea acerca de los productos, servicios e iniciativa del responsable. En el caso de que no acepte el tratamiento de sus datos de carácter personal, no podremos atender su consulta.
En el caso de que nos otorgue su consentimiento, sus datos serán tratados para mantenerle informado de las actividades, promociones y novedades empresariales, científicas y formativas.
Adicionalmente, podremos utilizar sus datos de forma anonimizada para realizar un seguimiento estadístico de nuestro servicio de atención al usuario, considerando que contamos con un interés legítimo en la mejora continua de los procesos internos de respuesta.
Destinatarios
Los datos de carácter personal que nos facilite a través de la página web no serán comunicados a terceros, salvo en el caso de que fuesen requeridos por una autoridad administrativa o judicial. No obstante, tendrán acceso a sus datos aquellas empresas que nos presten servicios que requieran de dicho acceso, como empresas de servicios informáticos o de desarrollo web. Todos ellos están obligados contractualmente a mantener la confidencialidad de sus datos y a no utilizarlos para otra finalidad distinta al servicio que nos prestan.
Sus datos no serán cedidos a terceros. No obstante, podrán tener acceso a sus datos proveedores que nos prestan servicios, como, proveedores de servicios médicos, investigadores científicos que colaboran con nosotros o empresas de servicios informáticos.
Si lo desea, puede solicitar un listado completo de las categorías de proveedores que tendrán acceso a sus datos en la dirección indicada en la presente Política.
Plazos de conservación
Sus datos serán tratados hasta la resolución de consulta. Posteriormente podrán ser conservados anonimizados con fines estadísticos y de mejora de la calidad del servicio.
Derechos
Puede ejercitar sus derechos de accesos, rectificación, supresión, oposición limitación y portabilidad, así como efectuar cualquier consulta acerca del tratamiento de sus datos de carácter personal, dirigiéndose al Data Protection Officer (DPO) a través de los siguientes canales:
Recuerde acompañar copia de DNI para que podamos verificar su identidad.
Puede obtener más información acerca de sus derechos en los apartados 3 y 4 de la presente Política.
En el caso de no estar conforme con el tratamiento de sus datos de carácter personal, puede dirigirse a la Agencia Española de Protección de Datos.
Apartado “TRABAJA CON NOSOTROS” https://www.ascires.com/hospital/trabaja-con-nosotros/
Información adicional de protección de datos
Finalidad/es
Gestionar su participación en los procesos de selección de personal de las entidades de Ascires. Es necesario que consienta el tratamiento de sus datos de carácter personal para esta finalidad, de lo contrario no podremos incluirle en los procesos de selección.
Destinatarios
Los datos de carácter personal que nos facilite a través de la página web no serán comunicados a terceros, salvo en el caso de que fuesen requeridos por una autoridad administrativa o judicial. No obstante, tendrán acceso a sus datos aquellas empresas que nos presten servicios que requieran de dicho acceso, como empresas de servicios informáticos o de desarrollo web. Todos ellos están obligados contractualmente a mantener la confidencialidad de sus datos y a no utilizarlos para otra finalidad distinta al servicio que nos prestan.
Plazos de conservación
Sus datos serán conservados durante un año, salvo que nos autorice a conservarlo durante un periodo superior durante los procesos de selección en los que participe.
Derechos
Puede ejercitar sus derechos de accesos, rectificación, supresión, oposición limitación y portabilidad, así como efectuar cualquier consulta acerca del tratamiento de sus datos de carácter personal, dirigiéndose al Data Protection Officer (DPO) a través de los siguientes canales:
Recuerde acompañar copia de DNI para que podamos verificar su identidad.
Puede obtener más información acerca de sus derechos en los apartados 3 y 4 de la presente Política.
En el caso de no estar conforme con el tratamiento de sus datos de carácter personal, puede dirigirse a la Agencia Española de Protección de Datos.
Derechos de los que dispone.
De conformidad con la legislación vigente, usted cuenta con una serie de derechos en relación con el tratamiento de sus datos de carácter personal. Estos derechos reconocidos son los siguientes:
Derechos de acceso y rectificación: Tiene derecho a conocer el uso que se hace de sus datos personales, y en particular, el derecho a obtener información sobre si éstos están siendo objeto de tratamiento y, en su caso, la finalidad del mismo, así como la información disponible sobre el origen de dichos datos y las comunicaciones realizadas o previstas de los mismos.
Asimismo, usted tiene derecho a solicitar la modificación y actualización de sus datos.
Derecho a la supresión: Tiene derecho a solicitar que sus datos se eliminen, siempre y cuando no prevalezcan otros motivos legítimos para la conservación de sus datos.
Derecho de oposición: Usted tiene derecho a oponerse al tratamiento de sus datos personales en cualquier momento, siempre y cuando no prevalezcan otros motivos legítimos para el tratamiento de sus datos.
Derecho a la portabilidad: Se trata del derecho a que sus datos de carácter personal le sean facilitados en un formato estructurado, de uso común y lectura mecánica. El derecho a la portabilidad e los datos de carácter personal procederá cuando:
Derecho a la limitación del tratamiento: Tiene derecho a limitar el tratamiento de sus datos personales, de tal forma que sólo puedan ser conservados por el responsable, sin que se posible realizar otro tratamiento o emplearlos para una finalidad distinta. El derecho a la limitación del tratamiento será procedente cuando:
Derecho a presentar una reclamación ante la autoridad competente: En el caso de no estar conforme con el tratamiento de sus datos de carácter personal, puede efectuar una reclamación ante la Agencia Española de Protección de Datos.
ASCIRES trabajará para responder sus solicitudes de ejercicio de derechos a la mayor brevedad, procediendo a ejecutar la petición a la mayor brevedad siempre y cuando resulte procedente en atención a las características del tratamiento de datos de carácter personal.
Delegado de Protección de datos o Data Protection Officer (DPO)
ASCIRES cuenta con un DPO designado ante la Agencia Española de Protección de Datos. Puede ejercitar sus derechos (ver apartado anterior), así como realizar cualquier consulta o sugerencia, contactando con el DPO de ASCIRES a través de:
Recuerde acompañar copia de DNI para que podamos verificar su identidad.
Seguridad de sus datos.
ASCIRES realiza un importante esfuerzo para garantizar la seguridad de sus datos y preservarlos de cualquier acceso no autorizado mediante la aplicación de medidas de seguridad informática y su actualización continua a fin de adecuarlo a los avances tecnológicos.
Acceso a sus datos por parte de terceros.
Los datos de carácter personal que nos facilite a través de la página web no serán comunicados a terceros, salvo en el caso de que fuesen requeridos por una autoridad administrativa o judicial. No obstante, tendrán acceso a sus datos aquellas empresas que nos presten servicios que requieran de dicho acceso, como empresas de servicios informáticos o de desarrollo web. Todos ellos están obligados contractualmente a mantener la confidencialidad de sus datos y a no utilizarlos para otra finalidad distinta al servicio que nos prestan.
Si lo desea, puede solicitar un listado completo de las categorías de proveedores que tendrán acceso a sus datos en la dirección indicada en la presente Política.
Dónde serán tratados sus datos de carácter personal.
Sus datos serán tratados en la Unión Europea, no obstante, cabe la posibilidad de que puedan ser transferidos a terceros países para la prestación de un servicio por parte de un proveedor. En tal caso, recibirá información específica acerca del proveedor, el país o países en el que sus datos serán tratados y las garantías ofrecidas para la protección de sus datos de carácter personal.